Impact
WP-Members Membership Plugin for WordPress contains an SQL Injection flaw in the 'order_by' attribute of the [wpmem_user_membership_posts] shortcode. The defect arises from insufficient sanitization and lack of prepared statements, allowing an attacker to append arbitrary SQL to the query. If successful, the attacker can read sensitive database content. This weakness is classified as CWE-89.
Affected Systems
All versions of the WP-Members Membership Plugin up to and including 3.5.5.1 are affected. The plugin is distributed by cbutlerjr for the WordPress platform.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is less than 1%, suggesting a low likelihood of current exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with Contributor or higher privileges, so the attack vector is an authenticated web console user.
OpenCVE Enrichment